<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<Events>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}"/>
      <EventID>5382</EventID>
      <Version>0</Version>
      <Level>0</Level>
      <Task>13824</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8020000000000000</Keywords>
      <TimeCreated SystemTime="2020-06-05T12:31:06.0151594Z"/>
      <EventRecordID>580</EventRecordID>
      <Correlation/>
      <Execution ProcessID="668" ThreadID="772"/>
      <Channel>Security</Channel>
      <Computer>DESKTOP-4AR7BIA</Computer>
      <Security/>
    </System>
    <EventData>
      <Data Name="SubjectUserSid">S-1-5-18</Data>
      <Data Name="SubjectUserName">WIN-VJP8LBM74F9$</Data>
      <Data Name="SubjectDomainName">WORKGROUP</Data>
      <Data Name="SubjectLogonId">0x3e7</Data>
      <Data Name="SchemaFriendlyName">NGC Local Accoount Logon Vault Resource Schema</Data>
      <Data Name="Schema">{1d4350a3-330d-4af9-b3ff-a927a45998ac}</Data>
      <Data Name="Resource">NGC Local Accoount Logon Vault Resource</Data>
      <Data Name="Identity">010500000000000515000000620479610991A87285127E7BE9030000</Data>
      <Data Name="PackageSid"/>
      <Data Name="Flags">0</Data>
      <Data Name="ReturnCode">1168</Data>
      <Data Name="ProcessCreationTime">2020-06-05T12:31:05.9732070Z</Data>
      <Data Name="ClientProcessId">6664</Data>
    </EventData>
  </Event>
</Events>
